How to Fix SSL Certificate Errors
Five distinct errors, five distinct fixes. Diagnose first.
SSL errors: expired cert, wrong hostname, self-signed, incomplete chain, mixed content. Identify which one and fix it.
Five distinct errors, five distinct fixes. Diagnose first.
SSL errors: expired cert, wrong hostname, self-signed, incomplete chain, mixed content. Identify which one and fix it.
"SSL certificate error" is a category, not a single problem. Browsers and curl report different messages for different failures, and the fix depends on which one you're hitting. The common ones: expired certificate, wrong hostname (the cert is for example.com but you're hitting www.example.com), self-signed or untrusted CA, incomplete chain (intermediate cert not served), and mixed content (HTTPS page loading HTTP resources).
Before fixing anything, get the exact error. In Chrome, click the "Not secure" warning and read the certificate details. In curl, run `curl -v https://yourdomain` and read the TLS handshake output. In OpenSSL, `openssl s_client -connect yourdomain:443 -servername yourdomain` shows the full chain and any errors. Diagnosing from the actual error saves you from fixing the wrong thing.
For an expired certificate, the only fix is to renew and install a new one. If you're using Let's Encrypt, run the renewal manually (`certbot renew`) and check why auto-renewal failed — usually a stopped cron job, a changed DNS challenge, or port 80 being blocked. For a paid cert, order a renewal from your CA and install it before the old one expires.
For a wrong-hostname error, the certificate's Common Name or SAN list doesn't include the hostname you're accessing. Either reissue the cert with the correct hostname(s) in the SAN list, or fix your DNS/config so traffic hits a hostname the cert covers. For a self-signed error on a public site, replace the self-signed cert with one from a trusted CA (Let's Encrypt is free). Self-signed is fine for internal-only services where you can install the cert as a trusted root on the clients that connect.
An incomplete chain error means your server is sending the leaf certificate but not the intermediate(s) needed to chain back to a trusted root. Browsers that cache the intermediate may work; others won't. The fix is to configure your web server to serve the full chain file (leaf + intermediates) — in Nginx, `ssl_certificate` should point at the fullchain file; in Apache, the `SSLCertificateChainFile` or the chain bundled into `SSLCertificateFile`. Test with the SSL Labs analyzer to confirm the chain is complete.
Mixed content is a different beast: the page itself loads over HTTPS, but it references HTTP assets (images, scripts, stylesheets). Browsers block the insecure resources, breaking the page. The fix is to update all asset URLs to HTTPS, set a strict Content-Security-Policy with `upgrade-insecure-requests`, or add an HSTS header. SurePing's SSL monitoring checks the certificate chain and expiry daily on every plan, so you'll get warned 30 days before expiry instead of finding out from your users.